Live session monitoring
Watching an active privileged session in real time — a redacted activity log, not video — sending a message to viewers, terminating from the viewer, and how it relates to session recording.
Live session monitoring lets an authorised viewer watch a privileged session while it is happening, rather than only reviewing the recording afterward. Open it with Watch live, next to Terminate, on any active session row in Privileged → Sessions, /pam/sessions.
It is independent of session recording, on purpose
What a viewer actually sees
The stream auto-scrolls to the newest entry unless you have scrolled up to read something earlier. A closed or ended session shows "The session ended. This stream has closed."
Sending a message, and terminating the session
A message you send from the viewer reaches other people watching this session — it does not reach the operator's own terminal, and there is no way to type into their session from here. Use it to coordinate with a co-watching colleague, not to communicate with the person under observation.
Terminate ends the operator's connection immediately and closes the live stream for everyone watching. It is confirm-gated, since it has an immediate, irreversible effect on someone else's active work.
Who can watch, and when
Watching a session is gated on the credential's safe having Master Policy's Live monitor control turned on — either at the organisation level or through a Master Policy exception — and on the viewer holding session-content management permission. The "Watch live" button is available on every active session row unconditionally; if either requirement is not met, you will see the platform's refusal inside the viewer itself when you try, rather than the button being hidden in advance.
What to read next
- Master Policy and its exceptions — the Live monitor control that gates this feature.
- Session recording and transcripts — the separate, stored counterpart to watching live.